Skip to content

Conversation

@michelp
Copy link
Owner

@michelp michelp commented Oct 7, 2025

No description provided.

svenklemm and others added 4 commits August 8, 2024 07:23
The DO blocks in the version update scripts did not sufficiently
lock down search_path for the format calls allowing injection of
a malicious format function to be executed during upgrades.
@michelp michelp merged commit 38d2289 into main Oct 7, 2025
1 check passed
@michelp michelp deleted the fix/update-github-actions branch October 7, 2025 17:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants